The European Union is proposing a new way to weigh where cloud services are built, who controls them and which providers can handle the most sensitive public workloads. At the center of the package announced by the European Commission on June 3 is the proposed Cloud and AI Development Act, or CADA. Its purpose is not to remove foreign technology companies from Europe, but to reduce dependencies in areas the EU considers critical.
In brief
- The European Commission presented a technology sovereignty package on June 3, 2026, including proposed cloud and AI measures.
- The Cloud and AI Development Act aims to encourage EU data center construction and triple regional capacity within five to seven years.
- A four-level framework would apply increasingly strict sovereignty requirements to sensitive cloud uses.
- The proposals must be approved by EU member states and the European Parliament before becoming law.
For people and organizations that use online services, the immediate effect is unlikely to be a change in everyday apps. The more direct consequences would concern government projects, high-risk data storage and the infrastructure that supports digital services. The proposal remains a draft: it must be approved by EU member states and the European Parliament before it can become law.
Why cloud sovereignty has become a policy priority
Cloud computing is the infrastructure behind many public and private digital services, from data storage to software delivery. The Commission’s concern is that Europe relies heavily on providers headquartered outside the bloc. According to the Commission, non-EU companies provide more than 80% of the EU’s digital products, services, infrastructure and intellectual property, as France 24 reported.
That dependence is especially visible in cloud services. Amazon Web Services, Microsoft Azure and Google Cloud together provide around 70% of cloud services in Europe, according to the same report. The policy question is therefore not simply where a server is located. It is also whether a provider’s ownership, governance and legal obligations could matter when public authorities select infrastructure for highly sensitive work.

The debate intersects with the United States’ 2018 Cloud Act. The law allows US authorities to seek data held by US providers regardless of where it is stored. This does not mean that authorities automatically access data held in Europe, nor does it establish that every European data set is available to them. It does, however, help explain why the Commission is placing jurisdiction and control alongside physical data location in its sovereignty agenda.
Europe has already examined how control of data and infrastructure shapes its technology choices. Europe’s digital sovereignty debate around data control and artificial intelligence has increasingly focused on the practical relationship between regulation, services and infrastructure.
A four-level model for cloud services
The proposed framework would use four levels of cloud sovereignty. At the basic end, services would face a general requirement to keep data in Europe. Higher levels would bring stricter expectations for sensitive sectors, including security and defense. The structure is intended to distinguish between different types of workloads rather than apply identical conditions to every cloud use.
Public authorities would assess cloud services against sovereignty criteria, according to eWEEK’s account of the proposed package. Services that do not meet the required level could face restrictions in government projects or for the storage of high-risk data. The proposal therefore shifts the issue from a voluntary preference for local hosting toward a potential procurement and risk-assessment framework.
For public bodies, the practical change could be a more formal examination of the services used for sensitive operations. For cloud providers, the proposal could raise the importance of European operational control when competing for those contracts. It does not establish that US providers will be excluded from the European market. France 24 reported that EU technology chief Henna Virkkunen said the bloc was “not closing anyone out,” while stressing the importance of European providers in very critical sectors.

More data centers, with an uncertain legislative path
CADA also aims to encourage data center construction within the EU and to triple Europe’s data center capacity over five to seven years. That is an objective, not a guaranteed outcome. The proposal links the expansion of computing capacity to a broader effort to give Europe greater control over the physical systems used for cloud and AI services.
As TechRepublic reported, the package combines the cloud proposal with initiatives involving semiconductors, open-source software and energy digitalization. This broader approach recognizes that sovereignty is not determined by one law or one data center. It involves the supply of hardware, software, energy and services that allow digital systems to operate.
The proposal also signals a change in public procurement. The Commission plans to favor European companies in the most sensitive cloud and AI contracts. That could affect how governments define risk, compare providers and set requirements for systems handling critical information. It may also create pressure for providers to demonstrate where control over their operations sits, rather than relying only on security or performance claims.
For now, the key distinction is between policy direction and enforceable rules. The Commission has set out a framework designed to make resilience and control more visible in technology decisions. Its final shape, its legal force and its impact on providers will depend on negotiations between EU institutions and member states.
Featured image. Source: Pexels. Credit: panumas nikhomkhai. License: Pexels License.
